
Field Notes
Data Localization Fragments the Multinational: A Geoeconomic Reading of the Cross-Border Data Wars
TL;DR: Data localization laws in China, Russia, India, Indonesia, and the EU force multinational tech firms to build jurisdiction-bound infrastructure, and Apple's 2018 transfer of Chinese iCloud keys to state-linked Guizhou-Cloud Big Data shows that infrastructure can become a government's standing access channel, not merely a compliance cost.
Key takeaways:
- Visa, Mastercard, and American Express missed the RBI's October 15, 2018 payment-data deadline; roughly 85 percent, including Google, Amazon, and WhatsApp, had already complied.
- The European Centre for International Political Economy estimates China's localization rules cut GDP by roughly 1.1 percent through lost investment and export competitiveness.
- Microsoft's EU Data Boundary, finished February 2025 after a three-phase build starting January 2023, cost more than 20 billion dollars in European infrastructure.
- U.S. hyperscalers hold more than 70 percent of the EU cloud market even as Brussels pushes EU-domiciled processing through its October 2025 Cloud Sovereignty Framework.
In February 2018, Apple moved Chinese iCloud accounts and encryption keys to servers run by Guizhou-Cloud Big Data, then majority state-owned, before control passed to China Telecom's Tianyi Cloud. Localization law had moved more than a server; it moved control.

The Geostrategic Mapping of a Fragmented Mandate Landscape
Data localization is now a dense, overlapping set of legal regimes forcing parallel infrastructure build-outs, jurisdiction by jurisdiction. By 2025-2026, "comply once, deploy globally" is no longer viable for a company operating across more than two or three of these markets.
- China's dual-track regime. The Personal Information Protection Law and Data Security Law require domestic storage of "important data" and a cross-border transfer assessment above set thresholds; March 2024 exemptions eased this, but the requirement for sensitive data remains intact.¹
- Russia's inspection-ready mandate. Federal Law No. 242-FZ requires domestic storage of citizens' personal data and gives authorities standing rights to inspect it on demand, with no reciprocal obligation.²
- India's sector-specific hard deadline. The RBI's April 2018 circular gave payment operators until October 15, 2018 to store payment data exclusively in India. Visa, Mastercard, and American Express missed it; roughly 85 percent, including Google and Amazon, had already complied.³
- Indonesia's revenue-linked penalty. Government Regulation 71 of 2019 requires electronic system operators serving Indonesian users to register with the Ministry of Communications and Informatics and grant authorities system access. Penalties, effective October 2024, run up to 2 percent of annual revenue.⁴
- The EU's procurement-driven sovereignty push. The bloc has no blanket localization law, but the Data Act, the EU Health Data Space regulation, and the October 2025 Cloud Sovereignty Framework push EU-domiciled processing for health and critical-infrastructure data.⁵

The Geostrategic Common Thread: State Control Over Corporate Infrastructure
Individually, these regimes look like compliance line items. Together, they share one logic: mandate local storage, then attach a domestic access right, turning a data center into a lever a government can pull.
- Custody follows the license, not the customer. Apple disclosed the GCBD/Tianyi operator "will have access to all data that you store on this service...under applicable law." Whoever holds the encryption keys, not whoever's name is on the app, controls access.⁶
- The legal environment behind the license matters as much as the license. China's National Intelligence Law obliges organizations there to support state intelligence work when directed, so localized data sits inside that obligation too.
- Hard deadlines force capital decisions, not policy memos. The RBI's six-month window was not advisory: card networks with centralized architectures had to build India-only processing on a fixed, publicly tracked clock.
- The aggregate cost is measurable, not theoretical. The European Centre for International Political Economy put the GDP drag from China's regime at roughly 1.1 percent, from lost investment and export competitiveness, mapping onto capital-budget items like duplicated data centers and separated pipelines.²
- Compliant infrastructure and infrastructure free of a foreign access right are not the same thing. Microsoft's EU Data Boundary, completed February 2025 after a three-phase build from January 2023, cost more than 20 billion dollars and involved "hundreds of product teams and thousands of developers." That spend shows what real separation costs when residency doesn't include a foreign government's standing access right.⁷

What Geostrategic Resilience Requires of the Operating Model
Treating localization as a legal problem misreads where the geopolitical risk sits: in the operating model, not the policy manual. Three things separate companies that manage this well from those that get surprised.
- A jurisdiction-by-jurisdiction access map, not a data-flow diagram. Boards need to know where data sits, which entity holds the keys, and whether mutual legal assistance or a unilateral demand governs any foreign request for it.
- A pre-negotiated consequence chain for a state access demand. Companies that get blindsided treat a data-access request as a novel event needing emergency review; companies that manage the risk have already decided what triggers notification to customers, headquarters, and home-jurisdiction regulators.
- Capital planning that treats localization as structural, not transitional. These costs do not amortize away. Each new mandate, and Vietnam, India, and Indonesia have all tightened requirements since 2022, adds a fixed cost to the operating model.
Fortius Intel note: Data localization has moved past the point where it can be managed as a compliance workstream. It restructures who has physical and legal custody of a company's most sensitive information, market by market, and that custody question is now a standing lever states hold over the firms that keep it.
Methodology: Analysis draws on Apple's 2018 iCloud China disclosures and subsequent reporting, the Reserve Bank of India's April 2018 payment data localization circular, ITIF's June 2025 review of Indonesia's Government Regulation 71, TrustArc's 2025-2026 analysis of global localization risk, Orrick's January 2026 review of EU cloud sovereignty regulation, and Microsoft's February 2025 EU Data Boundary completion announcement. All cited sources are publicly available.
Footnotes
1 Greenberg Traurig LLP, China Relaxes Requirements for Cross-Border Data Transfers, March 2024. Describes the Cyberspace Administration of China's new exemption provisions to the PIPL/DSL cross-border transfer regime. Available at https://www.gtlaw.com/en/insights/2024/3/china-relaxes-requirements-for-cross-border-data-transfers
2 TrustArc, Managing Data Localization Across Global Privacy Laws, 2025-2026. Cites Russia's Federal Law No. 242-FZ domestic storage and inspection-access requirements, and ECIPE modeling estimating a roughly 1.1 percent GDP impact from China's localization regime. Available at https://trustarc.com/resource/data-localization-global-privacy-laws/
3 Business Standard, Visa, Mastercard and American Express Miss RBI's Data Localisation Deadline, October 15, 2018; and Reserve Bank of India, Storage of Payment System Data (FAQs on circular DPSS.CO.OD.No 2785/06.08.005/2017-18, issued April 6, 2018). Confirms the six-month compliance window, the October 15, 2018 deadline, and that roughly 85 percent of payment operators had complied. Available at https://www.business-standard.com/article/companies/visa-mastercard-and-american-express-miss-rbi-s-data-localisation-deadline-118101501033_1.html and https://www.rbi.org.in/commonman/english/scripts/FAQs.aspx?Id=2995
4 Information Technology and Innovation Foundation, Indonesia's Data Localization Regulation, June 9, 2025. Details Government Regulation 71 of 2019, its October 2024 enforcement start, and penalties of up to 2 percent of annual revenue. Available at https://itif.org/publications/2025/06/09/indonesia-data-localization-regulation/
5 Orrick, Herrington & Sutcliffe LLP, Data Localization and the Sovereign Cloud: EU Cloud Regulations Explained, January 2026. Covers the EU Data Act, the European Health Data Space regulation, the European Commission's October 2025 Cloud Sovereignty Framework, and the greater-than-70-percent U.S. hyperscaler share of the EU cloud market. Available at https://www.orrick.com/en/Insights/2026/01/Data-Localization-and-the-Sovereign-Cloud-EU-Cloud-Regulations-Explained
6 AppleInsider, Chinese iCloud Data Moved to Servers Operated by State-Owned Telco, July 18, 2018. Documents the February 2018 transfer of Chinese iCloud accounts and encryption keys to Guizhou-Cloud Big Data and the subsequent handover to China Telecom's Tianyi Cloud. Available at https://appleinsider.com/articles/18/07/18/chinese-icloud-data-moved-to-servers-operated-by-state-owned-telco
7 Microsoft, Microsoft Completes Landmark EU Data Boundary, Offering Enhanced Data Residency and Transparency, February 26, 2025. States the three-phase build from January 2023 to February 2025 and more than 20 billion dollars in European AI and cloud infrastructure investment over the prior 16 months. Available at https://blogs.microsoft.com/on-the-issues/2025/02/26/microsoft-completes-landmark-eu-data-boundary-offering-enhanced-data-residency-and-transparency/
About the author
Shekhar Attri, Co-Founder & CTO. An Indian Army Special Forces veteran with 21 years of service and a gallantry medal, Shekhar's corporate security advisory work spans Singapore, India, the Philippines, and the UAE, alongside PhD research on machine intelligence under incomplete information.